Journalist Bart Pfankuch shares his research into the cybersecurity threats facing the state after several attacks hit communities large and small. He spoke with SDPB’s C.J. Keene.
A full transcript of the conversation is available below.
C.J. Keene: We’re sitting down with Bart Pfankuch. He’s the content director and a reporter for South Dakota Newswatch. Bart, how are you doing today? Good. Thanks for having me. So obviously, as somebody who’s out here in Rapid City with myself, one of the big questions right now is cybersecurity. Could you just speak a little bit on your reporting that you’ve been doing recently with this?
Bart Pfankuch: So we saw the big attack in Pennington County that shut down a lot of public facing programs. People couldn’t pay online and the communication systems in Pennington County were very upset and email shut down. Then Rapid City had a small attack on its sewage system. And the city of Mitchell’s had an email attack and they’ve had communication problems, had to delay some public meetings and things like that. So I thought it was a good time to look at, well, who’s doing this? What is it? Why? And what’s being done to prevent it? And what I found was that I talked to some experts for one article that So this is probably Russia, China, or Iran. And in this case, it’s most likely Iran doing things to just try to upset government and public operations in the country they’re at war with.
So also what I found was that the state does have a couple of programs it’s enacted to try to help communities, at least local governments, county and municipal government, try to strengthen their systems and fight off these attacks. And also I found that we turned down some federal money that could have helped in this area, and instead are spending state tax dollars to the tune of about $7 million on two programs, Secure SD and Project Boundary Fence that are run out of by an expert at Dakota State University in Madison.
Keene: So, we’ll get to that money in just a little bit here, but for now, let’s just talk about your experiences talking with the people who are most closely connected to these matters. What are you hearing when you’re having these conversations about where security is in South Dakota? Is there anything more that we can be doing? I guess, what do you hear?
Pfankuch: Yeah, there’s kind of two tracks to it. One is You know, what can government or a business do with their systems to try to prevent people from hacking in and stealing data, stealing personal information of residents or customers? And then there’s also the occasional attack where it’s a ransom attack where organized crime or it could be a nation state tries to get money by holding a system ransom and asking for money in order for systems to be restored. Mostly what we’re seeing in South Dakota has been these attacks on how government systems are working.
But they’re more frequent than you think. I called the Attorney General’s office and they take reports to any hack has to be reported. And so their Consumer Affairs Division has had 1,062 reports of hacks over the past five years, including 127 so far in 2026.
So, a lot of attempts to break into systems. And the number one way that that can be done is through email. Email is a fairly open communication system. And there’s a lot of ways for people to hack into email. But also, so there’s the systems part. And then there’s the user part. And that’s called the human firewall is what the experts like to call it. And that is you opening an email that you shouldn’t, clicking on a link that you shouldn’t, doing something that opens your computer to potential hacking and that could be things not changing your password, not having two level authentication, not having a secure password, changing it enough, those kind of things, but mostly making that decision at some point to click on something that you shouldn’t and opening the door to someone coming in and stealing your information.
So those are really the two tracks, the system wide and then the individual user.
Keene: So this is something that we’ve been covering in our newsroom as well and That was one of the questions that I had was, you know, this comes at a time when state government is announcing cuts. This comes at a time when Rapid City’s local government just announced its proposed budget would be cut as well. And I like saving money as much as the next person, but also are we covering this? And the answer that I got from the city was a lot of the times it is the human firewall that we really need to be trained on more than spending money. In your experience researching this, does it seem like the human firewall does need to be taught a lesson here? Or is this something that more money could potentially fix if we were to invest in our systems?
Pfankuch: Well, I think everyone involved believes that more training, more protections are needed. And we’ve seen the results when things can get lax or when the hackers get more aggressive. Now, does that cost a lot of money? I mean, teaching your employees to change their passwords or not click on links, It does cost money. There’s kind of an ironic part of this where you would think that a big city government would be where they’d really go because that’s where the money is, more employees, more opportunities to hack in.
But what we’ve actually seen in South Dakota is a couple of attacks in more rural counties. Brown County had a famous shutdown basically in 2020, and just last year, Tripp County, little Tripp County south of Mitchell, A city employee sent about $820,000 in city money to a fake account and that money hasn’t been found or no one’s been held accountable.
So I think the expenditure needs to come outside of the big cities because they tend to have programs. They have IT directors with staffs that run these training programs. But your county clerk in Hutchinson County or McCook County, have they been trained on fighting off hackers? Probably not. So that’s, I think, where there’s some efforts being made to try to reach those people. Because anyone who uses anything attached to the internet, whether it’s looking up something online or using the email, anything connected to the Internet is vulnerable.
And what the experts will tell you is that they’re under constant attack. They may fight a bunch of them off, like they like to say, as you probably have heard this, hackers only have to be right one time.
We have to be right every time. And I think that’s a good base level understanding of how common these attacks are and how ready you have to be to fight them off.
Keene: I don’t know about you, but it definitely made me reassess my own personal passwords the last few weeks when we hear about Pennington County and Rapid City. When you’re talking, when you’re thinking about your own personal footprint, are you at least like, Do these things ring in the back of your mind?
Pfankuch: Well, I was on the phone with Mike Waldner, who runs the two big state programs out of DSU. And I’ve got some fake phishing email, a text message and an email from Monument Health, my local health care provider. It had nothing to do with Monument Health. So I was phished, P-H-I-S-H, phishing, they’re going out and phishing for people to hack, while I was on the phone with the expert. And I thought that that was classic because that just showed how prevalent this is. But one thing he told me that is helpful, I think, to individuals is the .gov suffix on an email is vetted.
So anything that has .com or .org, not that they’re bad. South Dakota Newswatch uses SDNewswatch.org.
But if it’s asking for information or it wants you to update something in your system or it’s asking for money and it’s pretending to be government, only .gov is vetted by the federal government and is a safe source. governmental email address. So that’s one little tip you can use. But yeah, changing your password frequently, using two-level authentication where it sends a message to your phone and then you use that code to get in. Those are all things, basic things. And then if you’re not sure, don’t click on it.
I know that’s hard because sometimes you get things that, they’re smart. They know that, for example, you know, I’m a golfer. So they could send things to me from golf courses they do this kind of work and figure out who you are and what it is that you like. It’s, oh, wow, Heart Ranch Golf Course is reaching out to me with a promotion. Maybe I’ll click on that and see what that’s about.
You have to just be really careful. Anytime anyone’s asking for money, personal information, or wants to take you kind of to the next level, hey, click on this to see what’s up. Those are all sort of triggers that you can look at and try to avoid.
Keene: So beyond the personal now, we do kind of have to get back into the financial question. That Of course, with the state turning down money, what would you say has been the big downstream reactions to the state turning down federal dollars for these kinds of matters?
Pfankuch: You know, Governor Noem, her administration turned down several federal grants on a number of different fronts. Also declined to apply for some money that was available on the federal level. And that was a policy approach. We don’t want to add to the federal debt. The other argument is these may be unfunded mandates where it pays for one year, but not the subsequent years. And then does it pay for employees who are actually going to run these programs or oversee them? Those were their arguments in most cases for turning down the money.
So no one’s sitting around, I don’t think, looking back and saying, gee, if only. I mean, it is what it is. She made that decision. She was the governor. That’s the way it is. So instead, some lawmakers, not necessarily happy about it, Did allocate seven million dollars for these two programs. Project Boundary Fence and Secure SD to help county, municipal, local, county and state government agencies firm up their their cyber security.
And under one of the programs, they do, kind of exactly what we were just talking about. They send these emails to employees that have a, um, you know, a link, a hackable link. and see if they click on it. And if they click on it, it sends an alert to the people at DSU. They then contact that government agency or entity and say, hey, your employee clicked on this. You need some training in this area. You may need to beef up your security in order to prevent those emails from actually getting to them.
So there’s nothing magical or highly, highly sophisticated about these programs. It’s really just talking about what we’re talking about right now, and then making it part of your daily habit as a government employee. Because another thing that Mike Waldner from DSU told me was, we are forced to give a lot of our information to government.
You want to get a driver’s license, you want to register your vehicle, you want to pay your taxes. A lot of things require your social security number, your address, your name, various pieces of information about you personally. sometimes maybe even access to a checking account. That would be rare, but ways where you can pay with a credit card things that you owe to government. So we have a huge reliance on government to do things the right way. Now, if it’s a business and you don’t want to pay by credit card or you want to pay with a check, you can send that in or you can decline to do business with them if you don’t feel safe.
But when it comes to managing your life and interfacing with government, you really don’t have a choice. So his point was, we really have a great responsibility as a state and as government entities to protect consumer information.
And as hard as they try, sometimes they still fail.
Keene: So often, and correct me if I’m wrong on this, but often it is the case that if we turn down these dollars from the federal government, they will be sent to other states instead.
So, while it is, yes, principled to not want to add to the federal debt, to reject this money, is it also creating challenges by not giving us access to resources that are already being allocated?
Pfankuch: Yes. I mean, the long and short of it is we’re not getting the money. And you can look at it the way I think that former Governor Noem looked at it, and that was that, well, if we don’t need it, we don’t want it, we’re a frugal state. It’s a principled stance she took. But it is actually our money to begin with. I mean, we’re paying our federal taxes. We pay to the federal government in various ways, not just every April 15th. But there are ways that we’re paying for things on the federal level.
And so if you turn down highway money, for example, well, I’ve got a list of things where we’ve turned down some money in the past few years. Yeah, it’s either going back into the Treasury or it’s being divvied up to other states. So that’s really a couple different ways that that works.
One is it can go back to the treasury and sort of be back to federal money. The other one is, yeah, it’s gonna be divvied up among states that did apply or did enter into the program. And so you have to just decide, well, is it worth it to do that? And do we need the money? In a lot of cases, she had decided that we didn’t. And like I say, that’s on a number of fronts.
Keene: So, the last question that I have for you is just, is there any other examples, and I think you were starting to get to that. The other examples of, how perhaps we are maybe passing the buck from federal dollars to the state or local taxpayer or local municipalities? I think that’s one.
Pfankuch: Clearly, we didn’t get the federal cybersecurity money and we had to have cybersecurity, so we had to pay for it ourselves. I think that’s a very cut and dried example where you can see that, yeah, we didn’t get the $5 million, so we had to spend $7 million. Other things, you know, that we left some money on the table. up to $70 million for rebates for home energy retrofits and high efficiency appliances. That’s a way for people to buy more efficient HVAC systems or appliances. And so, you know, ultimately that’s kind of an environmental or maybe a climate change program.
That was $70 million. We didn’t apply for fence line monitoring. That was a system that would have tracked air quality outside industrial plants. That was about $400,000. We didn’t apply for summer food money for kids, EBT money for snacks and food for low-income children during the summer, one of 10 states that didn’t apply.
We passed up a share of $1 billion to adapt new energy codes for buildings. We declined money from the Trump administration to extend unemployment benefits after COVID. And the state returned $80 million in rental assistance grants also after the pandemic ended. So there’s a lot of cases where, you know, do you see it? Do you feel it? It’s hard to say. I think, you know, that’s for a policymaker to decide. There are some cases where the money for… adopting new building and energy codes, that would have prevented an estimated 42 metric tons of carbon dioxide emissions and could have saved each South Dakota homeowner about $9,000.
So you’ve got to make those calls. And luckily, I’m not in that position to make those. I’m not an elected official. I only have to report about them. our role as the media is to make sure people know about it. And if there’s accountability or you want to hold someone accountable, you need to know about it. And that’s, I think, what we’re both trying to do is just keep people informed.
Keene: A lot to chew on. Bart Pfankuch is the content director and a reporter for South Dakota Newswatch. Thank you so much for sitting down with us.
Pfankuch: Absolutely, C.J.
